Dear @paraswap, could you please display the full address in the warning box? So that 0xWho can reverse resolve the address to a readable name, which I rely on it to confirm the address.
@banteg@0xFrame True. It probably should try reverse resolve to a name using the local address book first, which is more practical.
Perhaps it could also display how many times the user has interacted with the contract in the past.
a frontend hijacking attack on Convex
this is exactly why the wallet should display a human-readable ENS name for the smart contract address they are interacting with;
and the reason I added this feature to @TallyCash 3 months ago: https://t.co/OJJzOh9Tzt
This happened in https://t.co/BZkB2la34f: the problem was them rolling a vulnerable LP token price oracle (sers, we have the correct one also!).
Conclusion: if ever in the future you feel like rolling your price oracle for our pools - ask us to check please
the attacker then sold the DOLA tokens for usdt and then sold usdt for wbtc and repaid the flashloan, netted ~$1.3m of profit.
btw, Curve also earned ~$3m fees out of these large vol trades.
.@InverseFinance now believes the crv3c is worth much more than it's actual value, so the attacker can borrow out 10m DOLA with only $4.7m worth of collateral.
that's ~$5m of bad debt to the protocol.
currently building a chrome ext which will show you a tooltip with a human readable name (from your address book) whenever you select an address.
it supports ENS reverse resolution; tells if it's a contract or EOA, + the ether balance.
this chrome ext is gonna be called: 0xWho?
We are honored to introduce the new ReportingDAO member, .@WatchPug_, a team of web3 security professionals!
In combination with WATHPUG, InsureDAO will be able to elevate security, privacy, and usability even more!!
https://t.co/K0Bo2qu7S0
#InsureDAO#DeFi
β οΈ Oct 20, 9 AM UTC, an attacker exploited PancakeHunny and stole 2.3M
The rootΒ cause: inappropriate usage of a low liquidity pool makes it vulnerable to price manipulation to create artificial profits
Read more: https://t.co/25lMmH5ydc